Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52066
Total
4132
Critical
15433
High
15137
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2021-27137 | HIGH | 8.1 | An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send … | Jul 16, 2026 |
| CVE-2026-9046 | HIGH | 7.0 | A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when … | Jul 16, 2026 |
| CVE-2026-6511 | MEDIUM | 5.5 | During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated … | Jul 16, 2026 |
| CVE-2026-63088 | HIGH | 8.6 | stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address … | Jul 16, 2026 |
| CVE-2026-63087 | CRITICAL | 9.8 | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the … | Jul 16, 2026 |
| CVE-2026-63086 | HIGH | 8.6 | text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the … | Jul 16, 2026 |
| CVE-2026-63085 | HIGH | 8.8 | Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field … | Jul 16, 2026 |
| CVE-2026-57074 | UNKNOWN | — | XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element … | Jul 16, 2026 |
| CVE-2026-57073 | CRITICAL | 9.1 | HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element … | Jul 16, 2026 |
| CVE-2026-55548 | MEDIUM | 4.3 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request … | Jul 16, 2026 |
| CVE-2026-55407 | UNKNOWN | — | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the decode_unknown_field function in buffa's protobuf decoder allocated heap memory … | Jul 16, 2026 |
| CVE-2026-55406 | UNKNOWN | — | Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView<V> type allowed safe Rust … | Jul 16, 2026 |
| CVE-2026-50012 | MEDIUM | 5.5 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in … | Jul 16, 2026 |
| CVE-2026-47751 | UNKNOWN | — | Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action checked … | Jul 16, 2026 |
| CVE-2026-47729 | MEDIUM | 6.5 | Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway … | Jul 16, 2026 |
| CVE-2026-46621 | CRITICAL | 9.1 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using … | Jul 16, 2026 |
| CVE-2026-46562 | CRITICAL | 9.8 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a … | Jul 16, 2026 |
| CVE-2026-45795 | MEDIUM | 5.3 | The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner … | Jul 16, 2026 |
| CVE-2026-45612 | MEDIUM | 5.5 | rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure … | Jul 16, 2026 |
| CVE-2026-45576 | UNKNOWN | — | zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such … | Jul 16, 2026 |
| CVE-2026-45568 | UNKNOWN | — | zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL … | Jul 16, 2026 |
| CVE-2026-45367 | HIGH | 7.5 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular … | Jul 16, 2026 |
| CVE-2026-45325 | HIGH | 8.2 | Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts … | Jul 16, 2026 |
| CVE-2026-44632 | CRITICAL | 9.1 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled … | Jul 16, 2026 |
| CVE-2026-44596 | MEDIUM | 6.5 | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, … | Jul 16, 2026 |